Privacy policy
Last updated 28 August 2026.
This notice explains how HumanDesign.AI LTD handles personal data in connection with Human Design MCP and the underlying Human Design API. It is written to meet our obligations under the UK GDPR and the Data Protection Act 2018.
The short version: calculation requests do not create a stored copy of the birth details you send. A request is calculated in memory and the result returned. Account-connected MCP tools may read or update data already held in your HumanDesign.ai account when you explicitly ask them to and have granted the required permission.
Who we are
HumanDesign.AI LTD is a company registered in England and Wales, company number 14696719, with its registered office at 128 City Road, London, EC1V 2NX. We operate Human Design MCP and the Human Design API and are the data controller for the account information of the people and companies who use them.
We are registered with the Information Commissioner's Office as a data controller under the Data Protection (Charges and Information) Regulations 2018. Write to support@humandesign.ai for any question about this notice or to exercise the rights described below.
Our different roles
This distinction matters, because it determines who is responsible for what.
For your account we are the controller. Your contact details, membership status, billing records, API key, OAuth grants and usage history are ours to hold and answer for.
For birth details sent for a calculation we are a processor, and you are the controller. When your product or agent sends us a date, time and place of birth belonging to one of your users, you decide why it is being processed and on what lawful basis. We act on your instruction, which is the tool call or API request itself, and do nothing else with it. Because we do not retain it as request content, our role begins and ends inside that calculation.
For account-connected tools we act within the signed-in user's existing HumanDesign.ai account. OAuth limits the MCP client to the capabilities, workspace and data the user authorized. Data deliberately saved to the account remains there under the account relationship; the MCP service does not create a separate copy for its own use.
What we process, why, and on what basis
Account and billing information such as name, email address, company, membership level and payment records. We process this to provide the service and to take payment, on the basis of our contract with you, and to meet accounting and tax obligations, on the basis of legal obligation. UK financial records are ordinarily kept for six years.
API keys, OAuth grants and usage records. Each request is checked against the active credential and permissions so that access and plan limits can be enforced. We record which operation was called and what it consumed. This is necessary to perform our contract with you, and we also rely on our legitimate interest in preventing abuse and keeping the service available to everyone.
Technical logs recording request paths, response codes and error types. These support reliability, security and abuse prevention, on the basis of our legitimate interests. They do not contain request bodies.
Birth details submitted with a calculation request are used to compute the chart and are discarded when the response is returned. The astronomical calculation runs inside our own service using a local ephemeris, so these details are not sent to any third party in order to produce a result.
For clarity: a date, time and place of birth is personal data, but it is not special category data under Article 9 of the UK GDPR. It is not health information, biometric data, or a measurement of anything about a person, and our service does not treat it as such.
What we do not do
We do not retain the content of calculation requests. We do not sell personal data. We do not use the birth details you send for our own purposes, for training models, for analytics or for marketing. We do not carry out automated decision making producing legal or similarly significant effects, and we do not profile the individuals whose details pass through the calculation service.
How long we keep things
Calculation request content is not kept, so there is no retention period, nothing to export and nothing to erase. Account and billing information is kept for as long as you hold an account and then for the period required by UK accounting and tax law. Usage records are kept for as long as needed to administer plans, resolve billing questions and investigate abuse. Technical logs are kept for a limited period determined by what is needed for reliability and security, and no longer. Data you deliberately save in HumanDesign.ai is retained under your account until you delete it or close the account, subject to legal retention duties.
Who else is involved
We use a small number of service providers, each engaged under terms that require them to act only on our instructions and to keep the data secure.
Railway hosts the API and MCP services in the European Economic Area. Cloudflare provides network and security services in front of them. Supabase stores the public reference data behind the celebrity endpoints, hosted in London. Our own account system at my.humandesign.ai validates credentials, permissions and usage. Payments are handled by our payment providers, who receive the details necessary to take payment and are controllers in their own right for that purpose.
Transfers outside the UK
Where personal data is processed outside the United Kingdom, it is processed within the European Economic Area, which the UK recognises as providing an adequate level of protection. If we ever need to use a provider in a country without that recognition, we will put an International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses in place first, together with any additional safeguards required.
Security
Access to calculation tools requires an API key or an authorized OAuth connection, checked on every call. Traffic is encrypted in transit. Keys belong on your own server; OAuth tokens belong in the client's protected credential store. Tell us promptly if a credential is exposed so it can be revoked or replaced. Not storing calculation request content is itself one of the strongest protections we can offer for the people whose details pass through.
Your rights
Under UK data protection law you have the right to be told how your data is used, to ask for a copy of it, to have inaccurate data corrected, to ask for erasure, to ask us to restrict processing, to object to processing carried out on the basis of legitimate interests, and to receive data you gave us in a portable form. Where we rely on consent you may withdraw it at any time without affecting what came before.
Write to support@humandesign.ai to exercise any of these. We will respond within one month and will not charge you. If your request concerns birth details your own product sent for a calculation, please note we hold none of that request content, and the person to approach is the operator of that product.
Complaints
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113, and doing so does not depend on raising it with us first.
Children
The calculation API is sold to developers and businesses and is not directed at children. If you build a product used by children, that responsibility and the associated obligations, including the Children's Code, sit with you as the controller. HumanDesign.ai account services may have separate age requirements presented during registration.
Changes
We may update this notice. Material changes will be notified by email to the address on your account or by notice on this site. The date above is the current version.